Betheme

Explore Betheme vulnerabilities across all versions. Currently tracking 21 known vulnerabilities, including severity, impact, and patch status.

01234567891017.11.2022Today17.11.20228.8Betheme <= 26.5.1.4 - Authenticated (Subscriber+) PHP Object Injection CVSS 8.8 · 17.11.202218.11.20228.8Betheme <= 26.5.1.4 - Authenticated (Subscriber+) PHP Object Injection CVSS 8.8 · 18.11.202221.11.20226.4Betheme <= 26.6.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization Checks to Private Page/Post Data Disclosure CVSS 4.3 · 21.11.20228.8Betheme <= 26.6.2 - Missing Authorization Check on Core Functionality CVSS 8.8 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization to Post Status Change CVSS 4.3 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization to Post Title Change CVSS 4.3 · 21.11.20224.3Betheme <= 26.6.2 - Missing Authorization to Theme Settings Update CVSS 4.3 · 21.11.202213.04.20236.1Betheme <= 26.7.5 - Reflected Cross-Site Scripting CVSS 6.1 · 13.04.202310.08.20236.5Betheme <= 27.1.1 - Missing Authorization via '_tool_history_delete' CVSS 6.5 · 10.08.202314.11.20236.3Betheme <= 27.1.1 - Missing Authorization CVSS 6.3 · 14.11.202329.08.20248.8Betheme <= 27.5.6 - Authenticated (Contributor+) PHP Object Injection CVSS 8.8 · 29.08.20246.4Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 29.08.202412.09.20246.4Betheme | Responsive Multipurpose WordPress & WooCommerce Theme <= 27.5.5 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File CVSS 6.4 · 12.09.202420.01.20256.4Betheme <= 27.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS CVSS 6.4 · 20.01.202515.04.20256.4Betheme <= 28.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 15.04.202505.08.20256.4Betheme <= 28.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 05.08.202506.10.20256.4Betheme <= 28.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 06.10.202508.10.20256.4Betheme <= 28.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_title' CVSS 6.4 · 08.10.202504.05.20266.5Betheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload' CVSS 6.5 · 04.05.20268.8Betheme <= 28.4 - Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload CVSS 8.8 · 04.05.2026

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage95%
Open

1

Fixed

20

Get automatic notifications for all Betheme vulnerabilities before they are exploited.

Vulnerability Records

21 records
2026-05-04 22:35CVE-2026-6261
8.8
High
WebbernautYes
2026-05-04 21:38CVE-2026-6262
6.5
Medium
WebbernautYes
2025-10-08 00:00CVE-2025-9371
6.4
Medium
Zbigniew PiotrakYes
2025-10-06 00:00CVE-2025-63075
6.4
Medium
João Pedro Soares de AlcântaraYes
2025-08-05 15:36CVE-2025-7399
6.4
Medium
stealthcopterYes
2025-04-15 19:05CVE-2025-3077
6.4
Medium
WebbernautYes
2025-01-20 21:55CVE-2025-0450
6.4
Medium
stealthcopterYes
2024-09-12 17:35CVE-2024-5567
6.4
Medium
wesley (wcraft)Yes
2024-08-29 16:16CVE-2024-3998
6.4
Medium
FoxyyyNo
2024-08-29 16:01CVE-2024-2694
8.8
High
Francesco CarlucciYes
Showing 1–10 of 21 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C